Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2g5j-5x95-r6hr: Unsafe tar unpacking in HashiCorp go-slug

HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving …/ and symlinks.

ghsa
#git

Unsafe tar unpacking in HashiCorp go-slug

High severity GitHub Reviewed Published Feb 6, 2023 to the GitHub Advisory Database • Updated Feb 6, 2023

ghsa: Latest News

GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS